Skip to main content

Help us improve the Digital Marketplace - send your feedback

Scout AI

Data and AI Platform - Secure Data Lab

Secure Data Lab is a unified data, integration and AI accelerator providing a controlled environment to securely ingest, govern, analyse and operationalise data. It offers pre-configured architecture, tooling and governance controls to rapidly deliver analytics, reporting and AI use cases while remaining cloud-agnostic and compliant.

Features

  • Cloud-agnostic data platform architecture
  • Secure data ingestion from multiple sources
  • Data integration, transformation, and orchestration
  • Built-in data governance and access controls
  • Analytics, reporting, and AI/ML enablement
  • API-first design for integration with existing systems
  • Secure Data Lab

Benefits

  • Faster time-to-value for data and AI initiatives
  • Reduced implementation risk through proven patterns
  • Improved data quality, governance, and security
  • Flexibility to operate across cloud environments
  • Supports evidence-based decision making
  • Compliant data analysis without risk of unauthorised access or leakage

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at david.smith@joinscout.org. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 8 9 9 0 0 5 4 4 7 5 7 0 2 8

Contact

Scout AI David Smith
Telephone: 07949413262
Email: david.smith@joinscout.org

About your service

Service categories

Application Development and Deployment

Data management

Database management systems

  • Relational Database Management Systems
  • Low-Code Database Management Systems
  • Navigational Database Management Systems
  • Fixed Record Database Management Systems
  • Object-Oriented Database Management Systems
  • Multivalue Database Management Systems
  • Non-Schematic Database Management Systems
  • Document-Oriented Database Systems
  • Key-Accessible Database Systems
  • Graph Database Management Systems
  • In-Memory Shared Data Managers
  • Data Lake Management Systems

Database administration and development

  • Database Administration
  • Database Replication
  • Data Modelling
  • Database Development and Optimization

Data integration and intelligence

  • Data Ingestion and Transformation Software
  • Dynamic Data Movement Software
  • Data Quality Software
  • Data Access Infrastructure Software
  • Composite Data Framework Software
  • Master Data Intelligence Software
  • Metadata Management Software
  • Data Archiving and Information LifD-Cycle Management
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Advanced analytics and AI model development
Data visualisation and dashboarding
Integration with third-party systems
Enhanced security and compliance controls
Training and enablement services
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud
Service constraints
Requires an existing or provisioned cloud environment
Internet connectivity required for SaaS components
Performance dependent on underlying cloud infrastructure
System requirements
  • Modern web browser
  • Secure network connectivity
  • Buyer-provided cloud tenancy where applicable

User support

Email or online ticketing support
Yes, at extra cost
Support response times
Support queries are acknowledged within 1 business hour during standard support hours (09:00–17:00 UK time, Monday to Friday, excluding UK public holidays).

Initial responses are typically provided within:

4 business hours for standard queries
1 business hour for urgent or service-impacting issues (where an enhanced support package applies)

Weekend response times

At weekends and UK public holidays:

Support queries are monitored

Urgent, service-impacting issues receive a response within 4 hours
Non-urgent queries are responded to on the next business day

Response times and support hours can be extended by agreement as part of an enhanced support package.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes, at an extra cost
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
Web chat functionality is designed and tested to meet accessibility requirements in line with WCAG 2.1 AA standards.

Testing activities include:

Keyboard-only navigation testing to ensure web chat can be accessed and operated without a mouse
Screen reader compatibility testing using commonly adopted assistive technologies (for example NVDA and VoiceOver)
Focus management and labelling checks to ensure messages, notifications, and controls are correctly announced
Colour contrast and text resizing checks to support users with visual impairments

Where third-party web chat components are used, the supplier relies on the vendor’s published accessibility conformance statements and undertakes internal validation as part of integration testing.

Accessibility feedback from users is reviewed and used to inform continuous improvement. Any identified accessibility issues are prioritised and addressed through the standard change and defect management process.
Onsite support
Yes, at extra cost
Support levels
The service is supported through tiered support levels aligned to buyer needs.

Standard Support (included)
Email and ticket-based support.
Support hours are 09:00–17:00 UK time, Monday to Friday, excluding UK public holidays.
Initial response is within 4 business hours for service-impacting incidents and 1 business day for non-urgent queries.
Access to documentation and knowledge base is provided.
The cost is included in the service price.
A dedicated technical account manager is not provided.

Enhanced Support (optional)
Email, ticketing, and phone support are provided.
Extended support hours include out-of-hours and weekend coverage.
Incidents are prioritised.
Initial response is within 1 hour for critical incidents.
An additional charge applies, either as a fixed annual fee or a percentage of the service subscription.
Access to a dedicated Technical Account Manager or Cloud Support Engineer is included.

Premium Support (optional)
Support is available 24×7×365.
Proactive monitoring and incident escalation are provided.
Initial response is within 30 minutes for critical incidents.
Pricing is quoted on request.
A named Technical Account Manager and Cloud Support Engineer are provided.

Support levels and pricing are agreed at contract award and may be varied by mutual agreement.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
Onboarding begins with an initiation phase to confirm use cases, security requirements, deployment model, and success criteria. The supplier then configures the service environment, access controls, and integrations in line with buyer requirements.

Users are supported through a combination of guided setup, training, and documentation. Online training sessions are provided to introduce the service, core features, and common workflows. Role-based training can be tailored for technical users, administrators, and business users. Onsite training can be provided as an optional, chargeable service where required.

Comprehensive user documentation is provided, including setup guides, user manuals, and operational runbooks. Documentation is available online and kept up to date throughout the contract.

During early use, the supplier provides hypercare support to resolve issues, answer questions, and ensure users are able to operate the service confidently. Ongoing support and refresher training can be provided as part of enhanced support packages.
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
End-of-contract data extraction
All customer data is stored and processed within the buyer’s own cloud or hosting environment, not in a shared supplier-managed data store.

As a result, no bulk data extraction is required at contract end. Buyers retain full access to their data, schemas, models, and configurations within their environment and can continue to use, migrate, or archive the data independently.

Where any service metadata, configurations, or operational artefacts are managed by the supplier, these can be exported by the buyer or provided by the supplier in standard, open formats on request.

At contract termination, the supplier supports an orderly offboarding process that includes removal of supplier access, confirmation of access revocation, and written assurance that no buyer data is retained by the supplier outside the buyer’s environment.
End-of-contract process
Describe what happens at the end of the contract

At the end of the contract, the service enters a managed offboarding phase. As customer data is hosted within the buyer’s own environment, the buyer retains full access to all data, configurations, and outputs without interruption.

The supplier removes all supplier-managed access to the service and associated tools, confirms access revocation, and provides written assurance that no buyer data is retained outside the buyer’s environment. Any supplier-managed service components are decommissioned in line with agreed security and change processes.

Support is provided to ensure a smooth transition, including handover of documentation and confirmation of contract closure.

Describe what’s included in the price of the contract and what’s an additional cost

Included in the contract price
Standard offboarding activities, including access removal, confirmation of data retention arrangements, and provision of existing documentation, are included. Ongoing access to data within the buyer’s environment does not incur additional cost.

Additional costs
Optional services such as extended transition support, additional documentation, bespoke data exports, migration to alternative platforms, or continued support beyond the contract end are chargeable and agreed separately.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
No
Application to install
No
Designed for use on mobile devices
No
Service interface
No
User support accessibility
WCAG 2.2 AA
API
No
Customisation available
Yes
Description of customisation
The service is designed to be configurable to support a wide range of use cases, from basic reporting and analytics to real-time data processing, secure environments, and scaled AI/ML workloads.

What can be customised
Data ingestion patterns, integration connectors, data models, and transformation logic can be configured to support batch, near real-time, or streaming data.
Analytics, dashboards, and AI/ML pipelines can be enabled or disabled based on use case.
Security controls, data access policies, network isolation, and encryption settings can be configured to meet organisational and regulatory requirements.
Infrastructure scaling, performance, and cost controls can be adjusted to match workload demands.

How users can customise
Customisation is carried out through configuration, policy settings, and APIs rather than source code changes.
Pre-defined templates and reference architectures are provided to accelerate setup for common use cases.

Who can customise
Authorised buyer administrators can configure the service within agreed permissions.
The supplier provides support, guidance, and optional professional services for more complex configurations.

Scaling

Independence of resources
The service is designed so that each buyer operates within a logically and operationally isolated environment.

Where the service is deployed into a buyer’s own cloud environment, compute, storage, and networking resources are dedicated to that buyer and are not shared. This ensures that demand from other users does not affect performance, availability, or security.

For any shared service components, isolation is enforced through tenant separation, role-based access controls, and resource quotas. Capacity management and auto-scaling are used to ensure workloads scale independently based on demand.

The supplier monitors resource utilisation and performance and applies scaling and capacity controls.

Analytics

Service usage metrics
Yes
Metrics types
The service provides usage and operational metrics to help buyers understand how the platform is being used and to support service management and optimisation.

Metrics available include service availability and uptime, performance and response times, data ingestion and processing volumes, and utilisation of platform components such as analytics, integration, and AI/ML services.

Security and operational metrics are also available, including access activity, authentication events, and error rates, subject to buyer permissions and configuration.

Where the service is deployed into the buyer’s own cloud environment, metrics are available through native cloud monitoring tools and dashboards.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
NCSC approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Degaussing
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
All customer data is stored and processed within the buyer’s own cloud or hosting environment.

Users export their data directly from their environment using native platform tools, standard database access, and APIs. This includes self-service export of datasets, analytics outputs, and AI/ML artefacts without reliance on the supplier.

Where supplier-managed components generate configuration or operational metadata, this can be exported by authorised users or provided by the supplier on request using standard, open formats.

The supplier provides guidance and documentation to support data export and, where required, optional assistance as part of enhanced support or professional services.
Data export formats
  • CSV
  • ODF
Data import formats
  • CSV
  • ODF

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)

Availability and resilience

Guaranteed availability
The service is designed to support high availability through resilient, cloud-based architecture.

Where the service is deployed into the buyer’s own cloud environment, overall availability depends on the underlying cloud platform selected by the buyer. The supplier configures the service in line with the cloud provider’s recommended availability and resilience patterns.

The supplier guarantees 99.9% availability for supplier-managed service components, measured monthly, excluding planned maintenance agreed in advance.

Availability targets, measurement methods, and exclusions are defined in the Service Level Agreement (SLA) provided with the service.

Service level agreements and refunds

If availability falls below the guaranteed level, buyers are eligible for service credits as set out in the SLA. Service credits are calculated as a percentage of the monthly service charge for the affected period and increase based on the severity and duration of the availability breach.

Service credits are applied to future invoices and represent the buyer’s sole remedy for failure to meet availability commitments.
Approach to resilience
The service is designed using resilient, cloud-native architecture to minimise the impact of component, service, or infrastructure failures.

Where deployed into a buyer’s cloud environment, resilience is achieved through the use of redundant compute, storage, and networking components, distributed across multiple availability zones within a region. The service supports automated scaling, health checks, and failover to maintain availability during periods of increased demand or partial failure.

Data resilience is provided through regular backups, replication, and recovery mechanisms aligned to buyer requirements and underlying cloud platform capabilities.

Datacentre resilience is provided by the third-party cloud service providers selected by the buyer. These datacentres are designed for high availability and include redundant power, cooling, network connectivity, and physical security controls. Datacentres are independently certified against recognised standards such as ISO/IEC 27001 and equivalent frameworks.

The supplier works within the shared responsibility model to ensure service configuration aligns with public sector resilience requirements. Further architectural and resilience details can be provided to buyers on request.
Outage reporting
Service outages and significant incidents are reported through multiple communication channels to ensure buyers are informed promptly.

Where applicable, a service status dashboard is made available to provide up-to-date information on service availability, incidents, and planned maintenance. This may include the use of the underlying cloud provider’s public status dashboard for infrastructure-related incidents.

Email notifications are used to alert nominated buyer contacts of service-impacting incidents, updates, and resolution status.

An API or machine-readable feed can be provided where supported, enabling buyers to integrate outage and status information into their own monitoring and service management tools.

Incident communications follow a defined process, including initial notification, regular updates during the incident, and a post-incident summary where appropriate.

The exact reporting mechanisms and notification channels are agreed with the buyer and documented as part of the service definition and support arrangements.

Identity and authentication

User authentication needed
No
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted to authorised users only and controlled through role-based access controls.

Administrative and management access is granted on the principle of least privilege and is limited to named, approved personnel. Strong authentication mechanisms are used, including multi-factor authentication where supported.

Support channels such as ticketing systems and collaboration tools are restricted to authenticated users and scoped to specific buyer accounts. Access is reviewed regularly and revoked promptly when no longer required.

All administrative access and support activity is logged and monitored to support audit and security oversight.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials Plus
Information security policies and processes
The supplier operates a formal information security management framework aligned to recognised industry standards and UK public sector best practice.

Information security policies cover areas including access control, data protection, incident management, vulnerability management, change management, asset management, and business continuity. Policies are documented, approved, and reviewed on a regular basis.

Overall accountability for information security sits with a named board-level executive. Day-to-day responsibility is delegated to senior operational and technical leads who oversee implementation and compliance.

Policies are enforced through defined processes, technical controls, and role-based access restrictions. Compliance is supported by staff training, mandatory security awareness activities, and onboarding checks.

Adherence to policies is monitored through logging, audit, and regular internal reviews. Any security incidents or policy breaches are managed through a formal incident management process, with escalation, reporting, and corrective actions tracked to closure.

Where the service is deployed within third-party cloud environments, the supplier operates within the shared responsibility model and ensures policies align with the cloud provider’s security controls and certifications.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
The service operates under a controlled configuration and change management process aligned to recognised industry best practice.

All service components are identified and tracked throughout their lifecycle using configuration records and version control. This includes infrastructure, components, configurations, and supporting documentation. Changes are logged, traceable, and auditable from request through implementation and retirement.

Proposed changes are assessed using a structured change process that considers operational, availability, and security impacts. Security assessment includes review of access controls, data handling, encryption, and risk to confidentiality, integrity, or availability.

Changes are approved by authorised personnel before implementation and are tested in non-production environments.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
The service operates a proactive vulnerability management process aligned to recognised industry best practice.

Potential threats to the service are assessed through regular vulnerability scanning, dependency reviews, and security assessments of infrastructure, platforms, and applications. Risks are evaluated based on severity, exploitability, and potential impact on confidentiality, integrity, and availability.

Patches and mitigations are prioritised according to risk. Critical and high-severity vulnerabilities are addressed as soon as practicable, with emergency changes deployed outside normal change windows where required.

Information about potential threats is obtained from multiple sources, including cloud provider security advisories, vendor notifications, trusted security mailing lists, vulnerability databases.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Protective monitoring is implemented through centralised logging, alerting, and automated monitoring of service components and access activity. Potential compromises are identified using security events, anomaly detection, and predefined alert thresholds.

When a potential compromise is detected, alerts are triaged immediately and handled through a formal incident management process, including investigation, containment, and remediation. Relevant buyer contacts are notified in line with agreed procedures.

Service-impacting or security incidents receive an initial response within 1 hour, with ongoing updates provided until resolution.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
The service operates a formal incident management process with predefined procedures for common operational and security events. Users report incidents via email, ticketing, or phone support, depending on their support level.

Incidents are logged, prioritised, and managed through defined escalation and resolution workflows. Buyers are kept informed through regular updates, and post-incident reports are provided for significant incidents, outlining root cause, impact, and corrective actions.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
4%
Between £1,000,001 and £2,500,000
6%
Between £2,500,001 and £5,000,000
8%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Volunteering opportunities for staff
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at david.smith@joinscout.org. Tell them what format you need. It will help if you say what assistive technology you use.